Windows 10 DLL File Information - advapi32.dll |
The following DLL report was generated by automatic DLL script that scanned and loaded all DLL files in the system32 directory of Windows 10, extracted the information from them, and then saved it into HTML reports. If you want to view a report of another DLL, go to the main page of this Web site.
General Information
File Description: | Advanced Windows 32 Base API |
File Version: | 10.0.10130.0 (fbl_impressive.150522-2224) |
Company: | Microsoft Corporation |
Product Name: | Microsoft® Windows® Operating System |
DLL popularity | Very High - 585 other DLL files in system32 directory are statically linked to this file. |
File Size: | 483 KB |
Total Number of Exported Functions: | 850 |
Total Number of Exported Functions With Names: | 849 |
Section Headers
Name | Virtual Address | Raw Data Size | % of File | Characteristics | Section Contains... |
---|---|---|---|---|---|
.text | 0x00001000 | 429,056 Bytes | 86.6% | Read, Execute | Code |
.data | 0x0006a000 | 9,216 Bytes | 1.9% | Write, Read | Initialized Data |
.idata | 0x0006e000 | 20,480 Bytes | 4.1% | Read | Initialized Data |
.didat | 0x00073000 | 1,024 Bytes | 0.2% | Write, Read | Initialized Data |
.rsrc | 0x00074000 | 1,536 Bytes | 0.3% | Read | Initialized Data |
.reloc | 0x00075000 | 19,968 Bytes | 4.0% | Read, Discardable | Initialized Data |
Static Linking
advapi32.dll is statically linked to the following files:msvcrt.dll
ntdll.dll
api-ms-win-eventing-controller-l1-1-0.dll
api-ms-win-eventing-consumer-l1-1-0.dll
KERNELBASE.dll
SECHOST.dll
api-ms-win-service-core-l1-1-1.dll
api-ms-win-service-core-l1-1-2.dll
api-ms-win-service-management-l1-1-0.dll
api-ms-win-service-management-l2-1-0.dll
api-ms-win-service-private-l1-1-1.dll
api-ms-win-service-winsvc-l1-2-0.dll
api-ms-win-core-namedpipe-l1-2-0.dll
api-ms-win-core-processthreads-l1-1-2.dll
api-ms-win-security-base-l1-2-0.dll
api-ms-win-security-base-private-l1-1-1.dll
api-ms-win-core-registry-l1-1-0.dll
api-ms-win-core-registry-l1-1-1.dll
api-ms-win-core-sysinfo-l1-2-1.dll
KERNEL32.dll
RPCRT4.dll
api-ms-win-core-timezone-l1-1-0.dll
api-ms-win-security-audit-l1-1-1.dll
api-ms-win-core-apiquery-l1-1-0.dll
api-ms-win-core-perfcounters-l1-1-0.dll
This means that when advapi32.dll is loaded, the above files are automatically loaded too. If one of these files is corrupted or missing, advapi32.dll won't be loaded.
General Resources Information
Resource Type | Number of Items | Total Size | % of File |
---|---|---|---|
Icons | 0 | 0 Bytes | 0.0% |
Animated Icons | 0 | 0 Bytes | 0.0% |
Cursors | 0 | 0 Bytes | 0.0% |
Animated Cursors | 0 | 0 Bytes | 0.0% |
Bitmaps | 0 | 0 Bytes | 0.0% |
AVI Files | 0 | 0 Bytes | 0.0% |
Dialog-Boxes | 0 | 0 Bytes | 0.0% |
HTML Related Files | 0 | 0 Bytes | 0.0% |
Menus | 0 | 0 Bytes | 0.0% |
Strings | 10 | 1,284 Bytes | 0.3% |
Type Libraries | 0 | 0 Bytes | 0.0% |
Manifest | 0 | 0 Bytes | 0.0% |
All Others | 4 | 289,457 Bytes | 58.4% |
Total | 14 | 290,741 Bytes | 58.7% |
Icons in this file
No icons found in this file
Cursors in this file
No cursors found in this file
Dialog-boxes list (up to 1000 dialogs)
No dialog resources in this file.
String resources in this dll (up to 1000 strings)
String ID | String Text |
---|---|
50001 | Disallowed |
50002 | Software will not run, regardless of the access rights of the user. |
50003 | Untrusted |
50004 | Allows programs to execute with only access to resources granted to open well-known groups, blocking access Administrator privileges, and personally granted rights. |
50005 | Restricted |
50006 | Software cannot access certain resources, such as cryptographic keys and credentials, regardless of the access rights of the user. |
50007 | Basic User |
50008 | Allows programs to execute as a user that does not have Administrator access rights, but can still access resources accessible by normal users. |
50009 | Unrestricted |
50010 | Software access rights are determined by the access rights of the user. |
COM Classes/Interfaces
There is no type library in this file with COM classes/interfaces information
Exported Functions List
The following functions are exported by this dll:A_SHAFinal | A_SHAInit |
A_SHAUpdate | AbortSystemShutdownA |
AbortSystemShutdownW | AccessCheck |
AccessCheckAndAuditAlarmA | AccessCheckAndAuditAlarmW |
AccessCheckByType | AccessCheckByTypeAndAuditAlarmA |
AccessCheckByTypeAndAuditAlarmW | AccessCheckByTypeResultList |
AccessCheckByTypeResultListAndAuditAlarmA | AccessCheckByTypeResultListAndAuditAlarmByHandleA |
AccessCheckByTypeResultListAndAuditAlarmByHandleW | AccessCheckByTypeResultListAndAuditAlarmW |
AddAccessAllowedAce | AddAccessAllowedAceEx |
AddAccessAllowedObjectAce | AddAccessDeniedAce |
AddAccessDeniedAceEx | AddAccessDeniedObjectAce |
AddAce | AddAuditAccessAce |
AddAuditAccessAceEx | AddAuditAccessObjectAce |
AddConditionalAce | AddMandatoryAce |
AddUsersToEncryptedFile | AddUsersToEncryptedFileEx |
AdjustTokenGroups | AdjustTokenPrivileges |
AllocateAndInitializeSid | AllocateLocallyUniqueId |
AreAllAccessesGranted | AreAnyAccessesGranted |
AuditComputeEffectivePolicyBySid | AuditComputeEffectivePolicyByToken |
AuditEnumerateCategories | AuditEnumeratePerUserPolicy |
AuditEnumerateSubCategories | AuditFree |
AuditLookupCategoryGuidFromCategoryId | AuditLookupCategoryIdFromCategoryGuid |
AuditLookupCategoryNameA | AuditLookupCategoryNameW |
AuditLookupSubCategoryNameA | AuditLookupSubCategoryNameW |
AuditQueryGlobalSaclA | AuditQueryGlobalSaclW |
AuditQueryPerUserPolicy | AuditQuerySecurity |
AuditQuerySystemPolicy | AuditSetGlobalSaclA |
AuditSetGlobalSaclW | AuditSetPerUserPolicy |
AuditSetSecurity | AuditSetSystemPolicy |
BackupEventLogA | BackupEventLogW |
BaseRegCloseKey | BaseRegCreateKey |
BaseRegDeleteKeyEx | BaseRegDeleteValue |
BaseRegFlushKey | BaseRegGetVersion |
BaseRegLoadKey | BaseRegOpenKey |
BaseRegRestoreKey | BaseRegSaveKeyEx |
BaseRegSetKeySecurity | BaseRegSetValue |
BaseRegUnLoadKey | BuildExplicitAccessWithNameA |
BuildExplicitAccessWithNameW | BuildImpersonateExplicitAccessWithNameA |
BuildImpersonateExplicitAccessWithNameW | BuildImpersonateTrusteeA |
BuildImpersonateTrusteeW | BuildSecurityDescriptorA |
BuildSecurityDescriptorW | BuildTrusteeWithNameA |
BuildTrusteeWithNameW | BuildTrusteeWithObjectsAndNameA |
BuildTrusteeWithObjectsAndNameW | BuildTrusteeWithObjectsAndSidA |
BuildTrusteeWithObjectsAndSidW | BuildTrusteeWithSidA |
BuildTrusteeWithSidW | CancelOverlappedAccess |
ChangeServiceConfig2A | ChangeServiceConfig2W |
ChangeServiceConfigA | ChangeServiceConfigW |
CheckForHiberboot | CheckTokenMembership |
ClearEventLogA | ClearEventLogW |
CloseCodeAuthzLevel | CloseEncryptedFileRaw |
CloseEventLog | CloseServiceHandle |
CloseThreadWaitChainSession | CloseTrace |
CommandLineFromMsiDescriptor | ComputeAccessTokenFromCodeAuthzLevel |
ControlService | ControlServiceExA |
ControlServiceExW | ControlTraceA |
ControlTraceW | ConvertAccessToSecurityDescriptorA |
ConvertAccessToSecurityDescriptorW | ConvertSDToStringSDDomainW |
ConvertSDToStringSDRootDomainA | ConvertSDToStringSDRootDomainW |
ConvertSecurityDescriptorToAccessA | ConvertSecurityDescriptorToAccessNamedA |
ConvertSecurityDescriptorToAccessNamedW | ConvertSecurityDescriptorToAccessW |
ConvertSecurityDescriptorToStringSecurityDescriptorA | ConvertSecurityDescriptorToStringSecurityDescriptorW |
ConvertSidToStringSidA | ConvertSidToStringSidW |
ConvertStringSDToSDDomainA | ConvertStringSDToSDDomainW |
ConvertStringSDToSDRootDomainA | ConvertStringSDToSDRootDomainW |
ConvertStringSecurityDescriptorToSecurityDescriptorA | ConvertStringSecurityDescriptorToSecurityDescriptorW |
ConvertStringSidToSidA | ConvertStringSidToSidW |
ConvertToAutoInheritPrivateObjectSecurity | CopySid |
CreateCodeAuthzLevel | CreatePrivateObjectSecurity |
CreatePrivateObjectSecurityEx | CreatePrivateObjectSecurityWithMultipleInheritance |
CreateProcessAsUserA | CreateProcessAsUserW |
CreateProcessWithLogonW | CreateProcessWithTokenW |
CreateRestrictedToken | CreateServiceA |
CreateServiceW | CreateTraceInstanceId |
CreateWellKnownSid | CredBackupCredentials |
CredDeleteA | CredDeleteW |
CredEncryptAndMarshalBinaryBlob | CredEnumerateA |
CredEnumerateW | CredFindBestCredentialA |
CredFindBestCredentialW | CredFree |
CredGetSessionTypes | CredGetTargetInfoA |
CredGetTargetInfoW | CredIsMarshaledCredentialA |
CredIsMarshaledCredentialW | CredIsProtectedA |
CredIsProtectedW | CredMarshalCredentialA |
CredMarshalCredentialW | CredProfileLoaded |
CredProfileLoadedEx | CredProfileUnloaded |
CredProtectA | CredProtectW |
CredReadA | CredReadByTokenHandle |
CredReadDomainCredentialsA | CredReadDomainCredentialsW |
CredReadW | CredRenameA |
CredRenameW | CredRestoreCredentials |
CredUnmarshalCredentialA | CredUnmarshalCredentialW |
CredUnprotectA | CredUnprotectW |
CredWriteA | CredWriteDomainCredentialsA |
CredWriteDomainCredentialsW | CredWriteW |
CredpConvertCredential | CredpConvertOneCredentialSize |
CredpConvertTargetInfo | CredpDecodeCredential |
CredpEncodeCredential | CredpEncodeSecret |
CryptAcquireContextA | CryptAcquireContextW |
CryptContextAddRef | CryptCreateHash |
CryptDecrypt | CryptDeriveKey |
CryptDestroyHash | CryptDestroyKey |
CryptDuplicateHash | CryptDuplicateKey |
CryptEncrypt | CryptEnumProviderTypesA |
CryptEnumProviderTypesW | CryptEnumProvidersA |
CryptEnumProvidersW | CryptExportKey |
CryptGenKey | CryptGenRandom |
CryptGetDefaultProviderA | CryptGetDefaultProviderW |
CryptGetHashParam | CryptGetKeyParam |
CryptGetProvParam | CryptGetUserKey |
CryptHashData | CryptHashSessionKey |
CryptImportKey | CryptReleaseContext |
CryptSetHashParam | CryptSetKeyParam |
CryptSetProvParam | CryptSetProviderA |
CryptSetProviderExA | CryptSetProviderExW |
CryptSetProviderW | CryptSignHashA |
CryptSignHashW | CryptVerifySignatureA |
CryptVerifySignatureW | DecryptFileA |
DecryptFileW | DeleteAce |
DeleteService | DeregisterEventSource |
DestroyPrivateObjectSecurity | DuplicateEncryptionInfoFile |
DuplicateToken | DuplicateTokenEx |
ElfBackupEventLogFileA | ElfBackupEventLogFileW |
ElfChangeNotify | ElfClearEventLogFileA |
ElfClearEventLogFileW | ElfCloseEventLog |
ElfDeregisterEventSource | ElfFlushEventLog |
ElfNumberOfRecords | ElfOldestRecord |
ElfOpenBackupEventLogA | ElfOpenBackupEventLogW |
ElfOpenEventLogA | ElfOpenEventLogW |
ElfReadEventLogA | ElfReadEventLogW |
ElfRegisterEventSourceA | ElfRegisterEventSourceW |
ElfReportEventA | ElfReportEventAndSourceW |
ElfReportEventW | EnableTrace |
EnableTraceEx | EnableTraceEx2 |
EncryptFileA | EncryptFileW |
EncryptedFileKeyInfo | EncryptionDisable |
EnumDependentServicesA | EnumDependentServicesW |
EnumDynamicTimeZoneInformation | EnumServiceGroupW |
EnumServicesStatusA | EnumServicesStatusExA |
EnumServicesStatusExW | EnumServicesStatusW |
EnumerateTraceGuids | EnumerateTraceGuidsEx |
EqualDomainSid | EqualPrefixSid |
EqualSid | EtwLogSysConfigExtension |
EventAccessControl | EventAccessQuery |
EventAccessRemove | EventActivityIdControl |
EventEnabled | EventProviderEnabled |
EventRegister | EventSetInformation |
EventUnregister | EventWrite |
EventWriteEndScenario | EventWriteEx |
EventWriteStartScenario | EventWriteString |
EventWriteTransfer | FileEncryptionStatusA |
FileEncryptionStatusW | FindFirstFreeAce |
FlushEfsCache | FlushTraceA |
FlushTraceW | FreeEncryptedFileKeyInfo |
FreeEncryptedFileMetadata | FreeEncryptionCertificateHashList |
FreeInheritedFromArray | FreeSid |
GetAccessPermissionsForObjectA | GetAccessPermissionsForObjectW |
GetAce | GetAclInformation |
GetAuditedPermissionsFromAclA | GetAuditedPermissionsFromAclW |
GetCurrentHwProfileA | GetCurrentHwProfileW |
GetDynamicTimeZoneInformationEffectiveYears | GetEffectiveRightsFromAclA |
GetEffectiveRightsFromAclW | GetEncryptedFileMetadata |
GetEventLogInformation | GetExplicitEntriesFromAclA |
GetExplicitEntriesFromAclW | GetFileSecurityA |
GetFileSecurityW | GetInformationCodeAuthzLevelW |
GetInformationCodeAuthzPolicyW | GetInheritanceSourceA |
GetInheritanceSourceW | GetKernelObjectSecurity |
GetLengthSid | GetLocalManagedApplicationData |
GetLocalManagedApplications | GetManagedApplicationCategories |
GetManagedApplications | GetMultipleTrusteeA |
GetMultipleTrusteeOperationA | GetMultipleTrusteeOperationW |
GetMultipleTrusteeW | GetNamedSecurityInfoA |
GetNamedSecurityInfoExA | GetNamedSecurityInfoExW |
GetNamedSecurityInfoW | GetNumberOfEventLogRecords |
GetOldestEventLogRecord | GetOverlappedAccessResults |
GetPrivateObjectSecurity | GetSecurityDescriptorControl |
GetSecurityDescriptorDacl | GetSecurityDescriptorGroup |
GetSecurityDescriptorLength | GetSecurityDescriptorOwner |
GetSecurityDescriptorRMControl | GetSecurityDescriptorSacl |
GetSecurityInfo | GetSecurityInfoExA |
GetSecurityInfoExW | GetServiceDisplayNameA |
GetServiceDisplayNameW | GetServiceKeyNameA |
GetServiceKeyNameW | GetSidIdentifierAuthority |
GetSidLengthRequired | GetSidSubAuthority |
GetSidSubAuthorityCount | GetStringConditionFromBinary |
GetThreadWaitChain | GetTokenInformation |
GetTraceEnableFlags | GetTraceEnableLevel |
GetTraceLoggerHandle | GetTrusteeFormA |
GetTrusteeFormW | GetTrusteeNameA |
GetTrusteeNameW | GetTrusteeTypeA |
GetTrusteeTypeW | GetUserNameA |
GetUserNameW | GetWindowsAccountDomainSid |
I_QueryTagInformation | I_ScGetCurrentGroupStateW |
I_ScIsSecurityProcess | I_ScPnPGetServiceName |
I_ScQueryServiceConfig | I_ScRegisterPreshutdownRestart |
I_ScSendPnPMessage | I_ScSendTSMessage |
I_ScSetServiceBitsA | I_ScSetServiceBitsW |
I_ScValidatePnPService | IdentifyCodeAuthzLevelW |
ImpersonateAnonymousToken | ImpersonateLoggedOnUser |
ImpersonateNamedPipeClient | ImpersonateSelf |
InitializeAcl | InitializeSecurityDescriptor |
InitializeSid | InitiateShutdownA |
InitiateShutdownW | InitiateSystemShutdownA |
InitiateSystemShutdownExA | InitiateSystemShutdownExW |
InitiateSystemShutdownW | InstallApplication |
IsTextUnicode | IsTokenRestricted |
IsTokenUntrusted | IsValidAcl |
IsValidRelativeSecurityDescriptor | IsValidSecurityDescriptor |
IsValidSid | IsWellKnownSid |
LockServiceDatabase | LogonUserA |
LogonUserExA | LogonUserExExW |
LogonUserExW | LogonUserW |
LookupAccountNameA | LookupAccountNameW |
LookupAccountSidA | LookupAccountSidW |
LookupPrivilegeDisplayNameA | LookupPrivilegeDisplayNameW |
LookupPrivilegeNameA | LookupPrivilegeNameW |
LookupPrivilegeValueA | LookupPrivilegeValueW |
LookupSecurityDescriptorPartsA | LookupSecurityDescriptorPartsW |
LsaAddAccountRights | LsaAddPrivilegesToAccount |
LsaClearAuditLog | LsaClose |
LsaCreateAccount | LsaCreateSecret |
LsaCreateTrustedDomain | LsaCreateTrustedDomainEx |
LsaDelete | LsaDeleteTrustedDomain |
LsaEnumerateAccountRights | LsaEnumerateAccounts |
LsaEnumerateAccountsWithUserRight | LsaEnumeratePrivileges |
LsaEnumeratePrivilegesOfAccount | LsaEnumerateTrustedDomains |
LsaEnumerateTrustedDomainsEx | LsaFreeMemory |
LsaGetAppliedCAPIDs | LsaGetQuotasForAccount |
LsaGetRemoteUserName | LsaGetSystemAccessAccount |
LsaGetUserName | LsaICLookupNames |
LsaICLookupNamesWithCreds | LsaICLookupSids |
LsaICLookupSidsWithCreds | LsaLookupNames |
LsaLookupNames2 | LsaLookupPrivilegeDisplayName |
LsaLookupPrivilegeName | LsaLookupPrivilegeValue |
LsaLookupSids | LsaLookupSids2 |
LsaManageSidNameMapping | LsaNtStatusToWinError |
LsaOpenAccount | LsaOpenPolicy |
LsaOpenPolicySce | LsaOpenSecret |
LsaOpenTrustedDomain | LsaOpenTrustedDomainByName |
LsaQueryCAPs | LsaQueryDomainInformationPolicy |
LsaQueryForestTrustInformation | LsaQueryInfoTrustedDomain |
LsaQueryInformationPolicy | LsaQuerySecret |
LsaQuerySecurityObject | LsaQueryTrustedDomainInfo |
LsaQueryTrustedDomainInfoByName | LsaRemoveAccountRights |
LsaRemovePrivilegesFromAccount | LsaRetrievePrivateData |
LsaSetCAPs | LsaSetDomainInformationPolicy |
LsaSetForestTrustInformation | LsaSetInformationPolicy |
LsaSetInformationTrustedDomain | LsaSetQuotasForAccount |
LsaSetSecret | LsaSetSecurityObject |
LsaSetSystemAccessAccount | LsaSetTrustedDomainInfoByName |
LsaSetTrustedDomainInformation | LsaStorePrivateData |
MD4Final | MD4Init |
MD4Update | MD5Final |
MD5Init | MD5Update |
MIDL_user_free_Ext | MSChapSrvChangePassword |
MSChapSrvChangePassword2 | MakeAbsoluteSD |
MakeAbsoluteSD2 | MakeSelfRelativeSD |
MapGenericMask | NotifyBootConfigStatus |
NotifyChangeEventLog | NotifyServiceStatusChange |
NotifyServiceStatusChangeA | NotifyServiceStatusChangeW |
NpGetUserName | ObjectCloseAuditAlarmA |
ObjectCloseAuditAlarmW | ObjectDeleteAuditAlarmA |
ObjectDeleteAuditAlarmW | ObjectOpenAuditAlarmA |
ObjectOpenAuditAlarmW | ObjectPrivilegeAuditAlarmA |
ObjectPrivilegeAuditAlarmW | OpenBackupEventLogA |
OpenBackupEventLogW | OpenEncryptedFileRawA |
OpenEncryptedFileRawW | OpenEventLogA |
OpenEventLogW | OpenProcessToken |
OpenSCManagerA | OpenSCManagerW |
OpenServiceA | OpenServiceW |
OpenThreadToken | OpenThreadWaitChainSession |
OpenTraceA | OpenTraceW |
OperationEnd | OperationStart |
PerfAddCounters | PerfCloseQueryHandle |
PerfCreateInstance | PerfDecrementULongCounterValue |
PerfDecrementULongLongCounterValue | PerfDeleteCounters |
PerfDeleteInstance | PerfEnumerateCounterSet |
PerfEnumerateCounterSetInstances | PerfIncrementULongCounterValue |
PerfIncrementULongLongCounterValue | PerfOpenQueryHandle |
PerfQueryCounterData | PerfQueryCounterInfo |
PerfQueryCounterSetRegistrationInfo | PerfQueryInstance |
PerfRegCloseKey | PerfRegEnumKey |
PerfRegEnumValue | PerfRegQueryInfoKey |
PerfRegQueryValue | PerfRegSetValue |
PerfSetCounterRefValue | PerfSetCounterSetInfo |
PerfSetULongCounterValue | PerfSetULongLongCounterValue |
PerfStartProvider | PerfStartProviderEx |
PerfStopProvider | PrivilegeCheck |
PrivilegedServiceAuditAlarmA | PrivilegedServiceAuditAlarmW |
ProcessIdleTasks | ProcessIdleTasksW |
ProcessTrace | QueryAllTracesA |
QueryAllTracesW | QueryRecoveryAgentsOnEncryptedFile |
QuerySecurityAccessMask | QueryServiceConfig2A |
QueryServiceConfig2W | QueryServiceConfigA |
QueryServiceConfigW | QueryServiceDynamicInformation |
QueryServiceLockStatusA | QueryServiceLockStatusW |
QueryServiceObjectSecurity | QueryServiceStatus |
QueryServiceStatusEx | QueryTraceA |
QueryTraceW | QueryUsersOnEncryptedFile |
ReadEncryptedFileRaw | ReadEventLogA |
ReadEventLogW | RegCloseKey |
RegConnectRegistryA | RegConnectRegistryExA |
RegConnectRegistryExW | RegConnectRegistryW |
RegCopyTreeA | RegCopyTreeW |
RegCreateKeyA | RegCreateKeyExA |
RegCreateKeyExW | RegCreateKeyTransactedA |
RegCreateKeyTransactedW | RegCreateKeyW |
RegDeleteKeyA | RegDeleteKeyExA |
RegDeleteKeyExW | RegDeleteKeyTransactedA |
RegDeleteKeyTransactedW | RegDeleteKeyValueA |
RegDeleteKeyValueW | RegDeleteKeyW |
RegDeleteTreeA | RegDeleteTreeW |
RegDeleteValueA | RegDeleteValueW |
RegDisablePredefinedCache | RegDisablePredefinedCacheEx |
RegDisableReflectionKey | RegEnableReflectionKey |
RegEnumKeyA | RegEnumKeyExA |
RegEnumKeyExW | RegEnumKeyW |
RegEnumValueA | RegEnumValueW |
RegFlushKey | RegGetKeySecurity |
RegGetValueA | RegGetValueW |
RegLoadAppKeyA | RegLoadAppKeyW |
RegLoadKeyA | RegLoadKeyW |
RegLoadMUIStringA | RegLoadMUIStringW |
RegNotifyChangeKeyValue | RegOpenCurrentUser |
RegOpenKeyA | RegOpenKeyExA |
RegOpenKeyExW | RegOpenKeyTransactedA |
RegOpenKeyTransactedW | RegOpenKeyW |
RegOpenUserClassesRoot | RegOverridePredefKey |
RegQueryInfoKeyA | RegQueryInfoKeyW |
RegQueryMultipleValuesA | RegQueryMultipleValuesW |
RegQueryReflectionKey | RegQueryValueA |
RegQueryValueExA | RegQueryValueExW |
RegQueryValueW | RegRenameKey |
RegReplaceKeyA | RegReplaceKeyW |
RegRestoreKeyA | RegRestoreKeyW |
RegSaveKeyA | RegSaveKeyExA |
RegSaveKeyExW | RegSaveKeyW |
RegSetKeySecurity | RegSetKeyValueA |
RegSetKeyValueW | RegSetValueA |
RegSetValueExA | RegSetValueExW |
RegSetValueW | RegUnLoadKeyA |
RegUnLoadKeyW | RegisterEventSourceA |
RegisterEventSourceW | RegisterIdleTask |
RegisterServiceCtrlHandlerA | RegisterServiceCtrlHandlerExA |
RegisterServiceCtrlHandlerExW | RegisterServiceCtrlHandlerW |
RegisterTraceGuidsA | RegisterTraceGuidsW |
RegisterWaitChainCOMCallback | RemoteRegEnumKeyWrapper |
RemoteRegEnumValueWrapper | RemoteRegQueryInfoKeyWrapper |
RemoteRegQueryValueWrapper | RemoveTraceCallback |
RemoveUsersFromEncryptedFile | ReportEventA |
ReportEventW | RevertToSelf |
SafeBaseRegGetKeySecurity | SaferCloseLevel |
SaferComputeTokenFromLevel | SaferCreateLevel |
SaferGetLevelInformation | SaferGetPolicyInformation |
SaferIdentifyLevel | SaferRecordEventLogEntry |
SaferSetLevelInformation | SaferSetPolicyInformation |
SaferiChangeRegistryScope | SaferiCompareTokenLevels |
SaferiIsDllAllowed | SaferiIsExecutableFileType |
SaferiPopulateDefaultsInRegistry | SaferiRecordEventLogEntry |
SaferiSearchMatchingHashRules | SetAclInformation |
SetEncryptedFileMetadata | SetEntriesInAccessListA |
SetEntriesInAccessListW | SetEntriesInAclA |
SetEntriesInAclW | SetEntriesInAuditListA |
SetEntriesInAuditListW | SetFileSecurityA |
SetFileSecurityW | SetInformationCodeAuthzLevelW |
SetInformationCodeAuthzPolicyW | SetKernelObjectSecurity |
SetNamedSecurityInfoA | SetNamedSecurityInfoExA |
SetNamedSecurityInfoExW | SetNamedSecurityInfoW |
SetPrivateObjectSecurity | SetPrivateObjectSecurityEx |
SetSecurityAccessMask | SetSecurityDescriptorControl |
SetSecurityDescriptorDacl | SetSecurityDescriptorGroup |
SetSecurityDescriptorOwner | SetSecurityDescriptorRMControl |
SetSecurityDescriptorSacl | SetSecurityInfo |
SetSecurityInfoExA | SetSecurityInfoExW |
SetServiceBits | SetServiceObjectSecurity |
SetServiceStatus | SetThreadToken |
SetTokenInformation | SetTraceCallback |
SetUserFileEncryptionKey | SetUserFileEncryptionKeyEx |
StartServiceA | StartServiceCtrlDispatcherA |
StartServiceCtrlDispatcherW | StartServiceW |
StartTraceA | StartTraceW |
StopTraceA | StopTraceW |
SystemFunction001 | SystemFunction002 |
SystemFunction003 | SystemFunction004 |
SystemFunction005 | SystemFunction006 |
SystemFunction007 | SystemFunction008 |
SystemFunction009 | SystemFunction010 |
SystemFunction011 | SystemFunction012 |
SystemFunction013 | SystemFunction014 |
SystemFunction015 | SystemFunction016 |
SystemFunction017 | SystemFunction018 |
SystemFunction019 | SystemFunction020 |
SystemFunction021 | SystemFunction022 |
SystemFunction023 | SystemFunction024 |
SystemFunction025 | SystemFunction026 |
SystemFunction027 | SystemFunction028 |
SystemFunction029 | SystemFunction030 |
SystemFunction031 | SystemFunction032 |
SystemFunction033 | SystemFunction034 |
SystemFunction035 | SystemFunction036 |
SystemFunction040 | SystemFunction041 |
TraceEvent | TraceEventInstance |
TraceMessage | TraceMessageVa |
TraceQueryInformation | TraceSetInformation |
TreeResetNamedSecurityInfoA | TreeResetNamedSecurityInfoW |
TreeSetNamedSecurityInfoA | TreeSetNamedSecurityInfoW |
TrusteeAccessToObjectA | TrusteeAccessToObjectW |
UninstallApplication | UnlockServiceDatabase |
UnregisterIdleTask | UnregisterTraceGuids |
UpdateTraceA | UpdateTraceW |
UsePinForEncryptedFilesA | UsePinForEncryptedFilesW |
WaitServiceState | WmiCloseBlock |
WmiDevInstToInstanceNameA | WmiDevInstToInstanceNameW |
WmiEnumerateGuids | WmiExecuteMethodA |
WmiExecuteMethodW | WmiFileHandleToInstanceNameA |
WmiFileHandleToInstanceNameW | WmiFreeBuffer |
WmiMofEnumerateResourcesA | WmiMofEnumerateResourcesW |
WmiNotificationRegistrationA | WmiNotificationRegistrationW |
WmiOpenBlock | WmiQueryAllDataA |
WmiQueryAllDataMultipleA | WmiQueryAllDataMultipleW |
WmiQueryAllDataW | WmiQueryGuidInformation |
WmiQuerySingleInstanceA | WmiQuerySingleInstanceMultipleA |
WmiQuerySingleInstanceMultipleW | WmiQuerySingleInstanceW |
WmiReceiveNotificationsA | WmiReceiveNotificationsW |
WmiSetSingleInstanceA | WmiSetSingleInstanceW |
WmiSetSingleItemA | WmiSetSingleItemW |
WriteEncryptedFileRaw |
Imported Functions List
The following functions are imported by this dll:- msvcrt.dll:
_errno _except_handler4_common _ftol2 _i64tow_s _strcmpi _ui64tow_s _ultow _ultow_s _vsnprintf _vsnwprintf _wcsicmp _wcsnicmp _wcstoi64 _wcstoui64 iswalpha iswctype mbstowcs memcmp memcpy memmove memset strchr strstr swprintf_s swscanf_s tolower wcscat_s wcschr wcscpy_s wcsncmp wcsncpy_s wcsrchr wcsstr wcstok_s wcstoul - ntdll.dll:
DbgPrint EtwEventRegister EtwEventUnregister EtwEventWrite EtwGetTraceEnableFlags EtwGetTraceEnableLevel EtwGetTraceLoggerHandle EtwRegisterTraceGuidsW EtwTraceMessage EtwUnregisterTraceGuids LdrLoadDll LdrUnloadDll NlsMbCodePageTag NtAlpcQueryInformation NtClose NtCompareTokens NtCreateFile NtCreateKey NtDeleteKey NtDeviceIoControlFile NtDuplicateToken NtEnumerateKey NtOpenFile NtOpenKey NtOpenKeyEx NtOpenProcessToken NtOpenSymbolicLinkObject NtOpenThreadToken NtQueryInformationFile NtQueryInformationProcess NtQueryInformationThread NtQueryInformationToken NtQueryKey NtQueryMultipleValueKey NtQueryMutant NtQueryObject NtQueryPerformanceCounter NtQuerySecurityObject NtQuerySymbolicLinkObject NtQuerySystemInformation NtQuerySystemTime NtQueryValueKey NtQueryVolumeInformationFile NtReadFile NtRenameKey NtReplaceKey NtSaveKey NtSaveMergedKeys NtSetInformationThread NtSetInformationToken NtSetSystemInformation NtSetValueKey NtTraceControl NtTraceEvent NtWaitForMultipleObjects NtWaitForSingleObject NtWriteFile RtlAbsoluteToSelfRelativeSD RtlAcquireSRWLockExclusive RtlAcquireSRWLockShared RtlAddAccessAllowedAce RtlAddAccessAllowedAceEx RtlAddAccessAllowedObjectAce RtlAddAccessDeniedAceEx RtlAddAccessDeniedObjectAce RtlAddAce RtlAddAuditAccessAceEx RtlAddAuditAccessObjectAce RtlAdjustPrivilege RtlAllocateAndInitializeSid RtlAllocateHandle RtlAllocateHeap RtlAnsiCharToUnicodeChar RtlAnsiStringToUnicodeSize RtlAnsiStringToUnicodeString RtlAppendUnicodeStringToString RtlAppendUnicodeToString RtlConvertSidToUnicodeString RtlCopySid RtlCopyString RtlCopyUnicodeString RtlCreateAcl RtlCreateQueryDebugBuffer RtlCreateSecurityDescriptor RtlCreateUnicodeString RtlCreateUnicodeStringFromAsciiz RtlDeleteCriticalSection RtlDeleteElementGenericTable RtlDeleteElementGenericTableAvl RtlDestroyHandleTable RtlDestroyQueryDebugBuffer RtlDetermineDosPathNameType_U RtlDllShutdownInProgress RtlDosPathNameToNtPathName_U RtlDosPathNameToRelativeNtPathName_U RtlDuplicateUnicodeString RtlEnterCriticalSection RtlEnumerateGenericTableAvl RtlEnumerateGenericTableWithoutSplaying RtlEqualSid RtlEqualUnicodeString RtlExpandEnvironmentStrings_U RtlFirstFreeAce RtlFormatCurrentUserKeyPath RtlFreeAnsiString RtlFreeAnsiString RtlFreeHandle RtlFreeHeap RtlFreeSid RtlGUIDFromString RtlGetAce RtlGetControlSecurityDescriptor RtlGetCurrentTransaction RtlGetDaclSecurityDescriptor RtlGetFullPathName_U RtlGetGroupSecurityDescriptor RtlGetLastNtStatus RtlGetNtProductType RtlGetOwnerSecurityDescriptor RtlGetSaclSecurityDescriptor RtlGetThreadPreferredUILanguages RtlGetVersion RtlImageNtHeader RtlImpersonateSelf RtlInitAnsiString RtlInitAnsiStringEx RtlInitUnicodeString RtlInitUnicodeStringEx RtlInitializeConditionVariable RtlInitializeConditionVariable RtlInitializeCriticalSection RtlInitializeGenericTable RtlInitializeGenericTableAvl RtlInitializeHandleTable RtlInitializeSid RtlInsertElementGenericTable RtlInsertElementGenericTableAvl RtlIntegerToUnicodeString RtlIpv4AddressToStringW RtlIpv6AddressToStringW RtlIsGenericTableEmpty RtlIsTextUnicode RtlIsValidIndexHandle RtlLeaveCriticalSection RtlLengthSecurityDescriptor RtlLengthSid RtlLookupElementGenericTable RtlLookupElementGenericTableAvl RtlMakeSelfRelativeSD RtlMultiByteToUnicodeN RtlNtStatusToDosError RtlNtStatusToDosErrorNoTeb RtlNumberGenericTableElements RtlOemStringToUnicodeString RtlOpenCurrentUser RtlPrefixUnicodeString RtlQueryPerformanceCounter RtlQueryProcessDebugInformation RtlQueryRegistryValuesEx RtlReAllocateHeap RtlReleaseRelativeName RtlReleaseSRWLockExclusive RtlReleaseSRWLockShared RtlRestoreLastWin32Error RtlRunOnceBeginInitialize RtlRunOnceExecuteOnce RtlSetDaclSecurityDescriptor RtlSetGroupSecurityDescriptor RtlSetOwnerSecurityDescriptor RtlSetSaclSecurityDescriptor RtlStringFromGUID RtlSubAuthorityCountSid RtlSubAuthoritySid RtlTimeToSecondsSince1970 RtlUnicodeStringToAnsiSize RtlUnicodeStringToAnsiString RtlUnicodeStringToInteger RtlUnicodeToMultiByteN RtlUnicodeToMultiByteSize RtlUpcaseUnicodeChar RtlValidAcl RtlValidRelativeSecurityDescriptor RtlValidSecurityDescriptor RtlValidSid RtlWaitOnAddress RtlWakeAddressAll RtlWakeAddressSingle WinSqmAddToStream - api-ms-win-eventing-controller-l1-1-0.dll:
sechost!ControlTraceW sechost!EnableTraceEx2 sechost!EnumerateTraceGuidsEx sechost!EventAccessControl sechost!EventAccessQuery sechost!EventAccessRemove sechost!QueryAllTracesW sechost!StartTraceW sechost!StopTraceW sechost!TraceSetInformation - api-ms-win-eventing-consumer-l1-1-0.dll:
sechost!CloseTrace sechost!OpenTraceW sechost!ProcessTrace - KERNELBASE.dll:
AreFileApisANSI CLOSE_LOCAL_HANDLE_INTERNAL CreateProcessAsUserA CreateProcessAsUserW DisablePredefinedHandleTableInternal GetPackagePath GetSystemDefaultUILanguage GetUserDefaultUILanguage LocalAlloc LocalReAlloc MapPredefinedHandleInternal PackageIdFromFullName RegCreateKeyExInternalA RegCreateKeyExInternalW RegDeleteKeyExInternalA RegDeleteKeyExInternalW RegKrnGetClassesEnumTableAddressInternal RegKrnGetHKEY_ClassesRootAddress RegKrnGetTermsrvRegistryExtensionFlags RegOpenKeyExInternalA RegOpenKeyExInternalW RemapPredefinedHandleInternal Sleep lstrcmpW lstrcmpiW lstrlenW - SECHOST.dll:
ControlTraceA QueryAllTracesA StartTraceA - api-ms-win-service-core-l1-1-1.dll:
sechost!EnumDependentServicesW sechost!EnumServicesStatusExW sechost!QueryServiceDynamicInformation sechost!RegisterServiceCtrlHandlerExW sechost!SetServiceStatus sechost!StartServiceCtrlDispatcherW - api-ms-win-service-core-l1-1-2.dll:
sechost!GetServiceDisplayNameW sechost!GetServiceKeyNameW - api-ms-win-service-management-l1-1-0.dll:
sechost!CloseServiceHandle sechost!ControlServiceExW sechost!CreateServiceW sechost!DeleteService sechost!OpenSCManagerW sechost!OpenServiceW sechost!StartServiceW - api-ms-win-service-management-l2-1-0.dll:
sechost!ChangeServiceConfig2W sechost!ChangeServiceConfigW sechost!NotifyServiceStatusChange sechost!QueryServiceConfig2W sechost!QueryServiceConfigW sechost!QueryServiceObjectSecurity sechost!QueryServiceStatusEx sechost!SetServiceObjectSecurity - api-ms-win-service-private-l1-1-1.dll:
sechost!I_ScRegisterPreshutdownRestart sechost!I_ScRpcBindA sechost!I_ScRpcBindW sechost!I_ScSetServiceBitsA sechost!I_ScSetServiceBitsW sechost!WaitServiceState - api-ms-win-service-winsvc-l1-2-0.dll:
sechost!ChangeServiceConfig2A sechost!ChangeServiceConfigA sechost!ControlService sechost!ControlServiceExA sechost!CreateServiceA sechost!NotifyServiceStatusChangeA sechost!OpenSCManagerA sechost!OpenServiceA sechost!QueryServiceConfig2A sechost!QueryServiceConfigA sechost!QueryServiceStatus sechost!RegisterServiceCtrlHandlerA sechost!RegisterServiceCtrlHandlerExA sechost!RegisterServiceCtrlHandlerW sechost!StartServiceA sechost!StartServiceCtrlDispatcherA - api-ms-win-core-namedpipe-l1-2-0.dll:
KernelBase!ImpersonateNamedPipeClient - api-ms-win-core-processthreads-l1-1-2.dll:
KernelBase!OpenProcessToken KernelBase!OpenThreadToken KernelBase!SetThreadToken kernel32!CreateThread kernel32!GetCurrentProcess kernel32!GetCurrentProcessId kernel32!GetCurrentThread kernel32!GetCurrentThreadId kernel32!GetPriorityClass kernel32!GetProcessId kernel32!OpenProcess kernel32!OpenThread kernel32!TerminateProcess - api-ms-win-security-base-l1-2-0.dll:
KernelBase!AccessCheck KernelBase!AccessCheckAndAuditAlarmW KernelBase!AccessCheckByType KernelBase!AccessCheckByTypeAndAuditAlarmW KernelBase!AccessCheckByTypeResultList KernelBase!AccessCheckByTypeResultListAndAuditAlarmByHandleW KernelBase!AccessCheckByTypeResultListAndAuditAlarmW KernelBase!AddAccessAllowedAce KernelBase!AddAccessAllowedAceEx KernelBase!AddAccessAllowedObjectAce KernelBase!AddAccessDeniedAce KernelBase!AddAccessDeniedAceEx KernelBase!AddAccessDeniedObjectAce KernelBase!AddAce KernelBase!AddAuditAccessAce KernelBase!AddAuditAccessAceEx KernelBase!AddAuditAccessObjectAce KernelBase!AdjustTokenGroups KernelBase!AdjustTokenPrivileges KernelBase!AllocateAndInitializeSid KernelBase!AllocateLocallyUniqueId KernelBase!AreAllAccessesGranted KernelBase!AreAnyAccessesGranted KernelBase!CheckTokenMembership KernelBase!ConvertToAutoInheritPrivateObjectSecurity KernelBase!CopySid KernelBase!CreatePrivateObjectSecurity KernelBase!CreatePrivateObjectSecurityEx KernelBase!CreatePrivateObjectSecurityWithMultipleInheritance KernelBase!CreateRestrictedToken KernelBase!CreateWellKnownSid KernelBase!DeleteAce KernelBase!DestroyPrivateObjectSecurity KernelBase!DuplicateToken KernelBase!DuplicateTokenEx KernelBase!EqualDomainSid KernelBase!EqualPrefixSid KernelBase!EqualSid KernelBase!FindFirstFreeAce KernelBase!FreeSid KernelBase!GetAce KernelBase!GetAclInformation KernelBase!GetFileSecurityW KernelBase!GetKernelObjectSecurity KernelBase!GetLengthSid KernelBase!GetPrivateObjectSecurity KernelBase!GetSecurityDescriptorControl KernelBase!GetSecurityDescriptorDacl KernelBase!GetSecurityDescriptorGroup KernelBase!GetSecurityDescriptorLength KernelBase!GetSecurityDescriptorOwner KernelBase!GetSecurityDescriptorRMControl KernelBase!GetSecurityDescriptorSacl KernelBase!GetSidIdentifierAuthority KernelBase!GetSidLengthRequired KernelBase!GetSidSubAuthority KernelBase!GetSidSubAuthorityCount KernelBase!GetTokenInformation KernelBase!GetWindowsAccountDomainSid KernelBase!ImpersonateAnonymousToken KernelBase!ImpersonateLoggedOnUser KernelBase!ImpersonateSelf KernelBase!InitializeAcl KernelBase!InitializeSecurityDescriptor KernelBase!InitializeSid KernelBase!IsTokenRestricted KernelBase!IsValidAcl KernelBase!IsValidSecurityDescriptor KernelBase!IsValidSid KernelBase!IsWellKnownSid KernelBase!MakeAbsoluteSD KernelBase!MakeSelfRelativeSD KernelBase!MapGenericMask KernelBase!ObjectCloseAuditAlarmW KernelBase!ObjectDeleteAuditAlarmW KernelBase!ObjectOpenAuditAlarmW KernelBase!ObjectPrivilegeAuditAlarmW KernelBase!PrivilegeCheck KernelBase!PrivilegedServiceAuditAlarmW KernelBase!QuerySecurityAccessMask KernelBase!RevertToSelf KernelBase!SetAclInformation KernelBase!SetFileSecurityW KernelBase!SetKernelObjectSecurity KernelBase!SetPrivateObjectSecurity KernelBase!SetPrivateObjectSecurityEx KernelBase!SetSecurityAccessMask KernelBase!SetSecurityDescriptorControl KernelBase!SetSecurityDescriptorDacl KernelBase!SetSecurityDescriptorGroup KernelBase!SetSecurityDescriptorOwner KernelBase!SetSecurityDescriptorRMControl KernelBase!SetSecurityDescriptorSacl KernelBase!SetTokenInformation - api-ms-win-security-base-private-l1-1-1.dll:
KernelBase!MakeAbsoluteSD2 - api-ms-win-core-registry-l1-1-0.dll:
KernelBase!RegCloseKey KernelBase!RegCopyTreeW KernelBase!RegCreateKeyExA KernelBase!RegCreateKeyExW KernelBase!RegDeleteKeyExA KernelBase!RegDeleteKeyExW KernelBase!RegDeleteTreeA KernelBase!RegDeleteTreeW KernelBase!RegDeleteValueA KernelBase!RegDeleteValueW KernelBase!RegDisablePredefinedCacheEx KernelBase!RegEnumKeyExA KernelBase!RegEnumKeyExW KernelBase!RegEnumValueA KernelBase!RegEnumValueW KernelBase!RegFlushKey KernelBase!RegGetKeySecurity KernelBase!RegGetValueA KernelBase!RegGetValueW KernelBase!RegLoadAppKeyA KernelBase!RegLoadAppKeyW KernelBase!RegLoadKeyA KernelBase!RegLoadKeyW KernelBase!RegLoadMUIStringA KernelBase!RegLoadMUIStringW KernelBase!RegNotifyChangeKeyValue KernelBase!RegOpenCurrentUser KernelBase!RegOpenKeyExA KernelBase!RegOpenKeyExW KernelBase!RegOpenUserClassesRoot KernelBase!RegQueryInfoKeyA KernelBase!RegQueryInfoKeyW KernelBase!RegQueryValueExA KernelBase!RegQueryValueExW KernelBase!RegRestoreKeyA KernelBase!RegRestoreKeyW KernelBase!RegSaveKeyExA KernelBase!RegSaveKeyExW KernelBase!RegSetKeySecurity KernelBase!RegSetValueExA KernelBase!RegSetValueExW KernelBase!RegUnLoadKeyA KernelBase!RegUnLoadKeyW - api-ms-win-core-registry-l1-1-1.dll:
KernelBase!RegDeleteKeyValueA KernelBase!RegDeleteKeyValueW KernelBase!RegSetKeyValueA KernelBase!RegSetKeyValueW - api-ms-win-core-sysinfo-l1-2-1.dll:
KernelBase!GetComputerNameExW KernelBase!GetLocalTime KernelBase!GetSystemDirectoryW KernelBase!GetSystemTime KernelBase!GetSystemTimeAsFileTime KernelBase!GetSystemWindowsDirectoryW KernelBase!GetTickCount - KERNEL32.dll:
CancelIoEx CloseHandle CompareFileTime CopyFileExW CreateEventW CreateFileMappingW CreateFileW CreateMutexW CreateThreadpoolIo DelayLoadFailureHook DeleteFileW DeviceIoControl DosDateTimeToFileTime DuplicateHandle EnumUILanguagesW ExpandEnvironmentStringsA ExpandEnvironmentStringsW FileTimeToDosDateTime FindClose FindFirstFileExW FindNextFileW FindResourceExW FormatMessageW FreeLibrary FreeLibraryAndExitThread GetCommandLineW GetComputerNameA GetComputerNameW GetFileAttributesExW GetFileAttributesW GetFileMUIPath GetFileSize GetFileSizeEx GetFileTime GetFullPathNameW GetLastError GetLongPathNameW GetModuleFileNameW GetModuleHandleExW GetModuleHandleW GetOverlappedResult GetProcAddress GetProcessHeap GetThreadUILanguage GetVolumeInformationW GetVolumePathNameW HeapFree IsWow64Process LoadLibraryA LoadLibraryExW LoadLibraryW LoadResource LocalFree LocalLock LocalUnlock LockResource MapViewOfFile MoveFileW MultiByteToWideChar OutputDebugStringW QueryPerformanceCounter ReadProcessMemory ReleaseMutex ResetEvent SearchPathW SetErrorMode SetEvent SetFileInformationByHandle SetFilePointer SetLastError SetUnhandledExceptionFilter SizeofResource SleepEx TermsrvDeleteKey TermsrvOpenUserClasses UnhandledExceptionFilter UnmapViewOfFile WaitForSingleObject WideCharToMultiByte Wow64DisableWow64FsRedirection Wow64RevertWow64FsRedirection WriteFile lstrcmpi ntdll!LdrResolveDelayLoadedAPI ntdll!RtlAllocateHeap ntdll!RtlDecodePointer ntdll!RtlDeleteCriticalSection ntdll!RtlEncodePointer ntdll!RtlEnterCriticalSection ntdll!RtlInitializeCriticalSection ntdll!RtlLeaveCriticalSection ntdll!RtlReAllocateHeap ntdll!TpCallbackUnloadDllOnCompletion ntdll!TpCancelAsyncIoOperation ntdll!TpReleaseIoCompletion ntdll!TpStartAsyncIoOperation - RPCRT4.dll:
I_RpcExceptionFilter I_RpcExceptionFilter I_RpcMapWin32Status I_RpcSNCHOption NdrClientCall4 RpcBindingBind RpcBindingCreateW RpcBindingFree RpcBindingFromStringBindingW RpcBindingSetAuthInfoA RpcBindingSetAuthInfoExW RpcBindingSetAuthInfoW RpcEpResolveBinding RpcRaiseException RpcSsDestroyClientContext RpcStringBindingComposeW RpcStringFreeW UuidFromStringW UuidToStringW - api-ms-win-core-timezone-l1-1-0.dll:
KernelBase!EnumDynamicTimeZoneInformation KernelBase!GetDynamicTimeZoneInformationEffectiveYears - api-ms-win-security-audit-l1-1-1.dll:
sechost!AuditComputeEffectivePolicyBySid sechost!AuditEnumerateCategories sechost!AuditEnumeratePerUserPolicy sechost!AuditEnumerateSubCategories sechost!AuditFree sechost!AuditLookupCategoryNameW sechost!AuditLookupSubCategoryNameW sechost!AuditQueryGlobalSaclW sechost!AuditQueryPerUserPolicy sechost!AuditQuerySecurity sechost!AuditQuerySystemPolicy sechost!AuditSetGlobalSaclW sechost!AuditSetPerUserPolicy sechost!AuditSetSecurity sechost!AuditSetSystemPolicy - api-ms-win-core-apiquery-l1-1-0.dll:
ntdll!ApiSetQueryApiSetPresence - api-ms-win-core-perfcounters-l1-1-0.dll:
KernelBase!PcwAddQueryItem KernelBase!PcwCollectData KernelBase!PcwCreateNotifier KernelBase!PcwCreateQuery KernelBase!PcwEnumerateInstances KernelBase!PcwRemoveQueryItem KernelBase!PcwSendNotification KernelBase!PcwSendStatelessNotification KernelBase!PcwSetQueryItemUserData